Known vulnerabilities in Experience Commerce
Vendor:
Sitecore
Software:
Experience Commerce
Software CPE:
cpe:2.3:a:sitecore:experience_commerce:*:*:*:*:*:*:*:*
Website:
https://www.sitecore.com/
Total vulnerabilities:
5
Public exploits:
1
Known exploited (KEV):
1
Highest CVSSv4 Score:
9.2
Breakdown by Severity Chart
Vulnerabilities (5)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU118743 - Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') CVE-2025-3600 |
CWE-470 | Medium | - | 25.11.2025 |
SB2025112527 SB2025112528 |
||
| #VU118742 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2025-53692 |
CWE-79 | Low | - | 25.11.2025 |
SB2025112521 |
||
| #VU118741 - Exposure of sensitive information to an unauthorized actor CVE-2025-53694 |
CWE-200 | Medium | - | 25.11.2025 |
SB2025112521 |
||
| #VU118740 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
CWE-22 | High | - | 25.11.2025 |
SB2025112520 |
||
| #VU114796 - Deserialization of Untrusted Data CVE-2025-53690 |
CWE-502 | Critical | - | 04.09.2025 |
SB2025090436 |